#VU123545 Double free in Linux kernel - CVE-2025-71238
Published: March 4, 2026
Vulnerability identifier: #VU123545
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-71238
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error within the qla2x00_update_optrom() function in drivers/scsi/qla2xxx/qla_bsg.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/057a5bdc481e58ab853117254867ffb22caf9f6e
- https://git.kernel.org/stable/c/27ac9679c43a09e54e2d9aae9980ada045b428e0
- https://git.kernel.org/stable/c/31f33b856d2324d86bcaef295f4d210477a1c018
- https://git.kernel.org/stable/c/708003e1bc857dd014d4c44278d7d77c26f91b1c
- https://git.kernel.org/stable/c/74e7458537cd9349cf019862e51491f670871707
- https://git.kernel.org/stable/c/871f6236da96c4a9712b8a29d7f555f767a47e95
- https://git.kernel.org/stable/c/c2c68225b1456f4d0d393b5a8778d51bb0d5b1d0
- https://git.kernel.org/stable/c/f2bbb4db0e4a4fbd5e649c0b5d8733f61da24720